Knowella

Anti-Bribery Risk Assessment Template

In the United Kingdom the risk assessment is not a supporting document for the anti-bribery programme. It is the foundation of the statutory defence, and since September 2025 it underpins three separate corporate offences rather than one. An organisation without a current, evidenced assessment has no defence to argue from.

KnowComplyAssessmentCMP-04345 fields across 6 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 37001 cl.4.5
Workspace
KnowComply
Form type
Assessment
Underpins
Three UK failure to prevent defences
Reviewed
Annually and on change

The short version

  • The UK now has three failure to prevent offences: bribery under the Bribery Act 2010, facilitation of tax evasion under the Criminal Finances Act 2017, and fraud under ECCTA, in force from 1 September 2025.
  • All three provide a procedures-based defence, and in each the risk assessment is what makes proportionality arguable. Without it there is nothing to calibrate the procedures against.
  • The Home Office guidance on failure to prevent fraud is more prescriptive than the earlier bribery and tax evasion guidance, and it states explicitly that risk assessment is the foundation for the other five principles.
  • Being regulated elsewhere does not mean your existing procedures automatically qualify. The guidance is clear that existing compliance mechanisms are a starting point, not a defence.
  • The failure to prevent fraud offence carries an unlimited fine, applies to large organisations across all sectors, and requires no proof of management involvement.
  • Smaller organisations are affected indirectly: they may be associated persons of large organisations and face contractual requirements flowed down to them.

What this is

What is an anti-bribery risk assessment?

What is an anti-bribery risk assessment?

A structured assessment of where an organisation is exposed to bribery and corruption, by geography, sector, transaction type, business model and third party relationship, and what controls address each exposure. It informs the design of the whole programme, and under UK law it is the element on which the statutory defence rests.

Why does the assessment matter so much legally?

Because the UK failure to prevent offences provide a defence only where procedures were adequate or reasonable, and both standards are judged as proportionate to risk. Proportionality cannot be demonstrated without an assessment establishing what the risk was. Home Office guidance on the fraud offence states directly that a thorough risk assessment is the foundation and that all other principles should be informed by it.

Scope

When is an anti-bribery risk assessment required?

The assessment establishes exposure and calibrates the programme. It is not the programme, and it is not the due diligence performed on individual counterparties.

Use this template when

  • Establishing the organisation-wide exposure by geography, sector, transaction type and business model
  • Assessing third party exposure: agents, distributors, consultants, customs brokers and joint venture partners
  • Reviewing after entering a new market, acquiring a business, or changing the intermediary model
  • Calibrating due diligence depth, approval thresholds and monitoring intensity to the assessed risk
  • Evidencing proportionality for the statutory defences under UK failure to prevent offences

Do not use it for

  • Individual counterparty due diligence, which applies the assessment's conclusions to a specific third party
  • The code of conduct and gifts and hospitality policy, which are controls the assessment informs
  • Whistleblowing arrangements, which are a separate mechanism with their own requirements
  • Payment and procurement fraud controls, which address a different offence with overlapping controls
  • Sanctions and export control screening, which is a distinct regime with strict liability characteristics

Compliance mapping

Which ISO 37001 cl.4.5 requirements does this satisfy?

Anti-bribery obligations combine a management system standard with criminal offences whose defences turn on the quality of the risk assessment.

ClauseRequirementWhere it lands
ISO 37001 cl.4.5Bribery risk assessment identifying, analysing, evaluating and prioritising bribery risk, reviewed regularlyExposure
Bribery Act 2010 s.7Corporate offence of failure to prevent bribery, with adequate procedures as the defenceHeader
Bribery Act guidance, principle 3Risk assessment as one of six principles underpinning adequate proceduresExposure
Criminal Finances Act 2017 ss.45-46Failure to prevent facilitation of UK and foreign tax evasion, with reasonable procedures as the defenceHeader
ECCTA 2023, failure to prevent fraudIn force 1 September 2025 for large organisations, with reasonable procedures as the only defenceHeader
FCPA anti-bribery and accounting provisionsProhibition on corrupt payments to foreign officials, plus books and records and internal controlsControls
ISO 37001 cl.8.2Due diligence on transactions, projects, business associates and personnel proportionate to assessed riskControls
ISO 37001 cl.9.2Internal audit of the anti-bribery management system at planned intervalsAssurance

What it does not cover

  • Counterparty due diligence, which applies the assessment to a specific third party before engagement.
  • Gifts, hospitality and facilitation payment policy, which are controls calibrated by the assessment.
  • Whistleblowing arrangements, which operate independently and have their own protections and timescales.
  • Sanctions and export control screening, a separate regime with different liability characteristics.
  • The books and records controls required under the FCPA accounting provisions, which sit with finance.

How to complete it

How to complete an anti-bribery risk assessment, step by step

An assessment that supports a legal defence has to show its working. Four things determine whether it does.

Assess by transaction, not only by geography

Identify the specific interactions where bribery is plausible: permits, licences, inspections, customs clearance, tender processes, tax settlements and anything mediated by an agent paid on outcome. Then establish who performs them, through whom, and with what oversight. A country risk score tells you the weather; this tells you where the exposure sits.

Cover associated persons explicitly

All three UK offences turn on acts by associated persons: employees, agents, subsidiaries, and anyone performing services for or on behalf of the organisation. The assessment has to reach them, and the guidance is clear that smaller organisations may find themselves subject to requirements flowed down contractually because they are associated persons of someone larger.

Do not assume existing compliance covers it

The Home Office guidance states that organisations should not duplicate existing work, and equally that existing regulatory compliance mechanisms do not automatically amount to reasonable procedures. The correct approach is to map what exists against the risks this assessment identified and to record where the gaps are, rather than asserting that a regulated business is therefore compliant.

Date it, own it, and review it on change

The defence is judged on procedures in place at the time of the offence. An assessment dated four years ago, covering a business that has since entered two markets and acquired a distributor, does not support proportionality for the current operation. Review annually and on any material change to markets, model or intermediaries.

What auditors find

Most common anti-bribery risk assessment findings

Findings here concern whether the assessment could actually support a defence.

FindingClauseWhat fixes it
Assessment based on country risk indices with no transaction-level analysis.ISO 37001 cl.4.5Identify the specific transactions and intermediaries where exposure arises.
Third parties and associated persons not covered.Bribery Act s.7All three UK offences turn on associated persons; the assessment must reach them.
Existing regulatory compliance cited as evidence of reasonable procedures.ECCTA guidanceMap existing controls against identified risks and record gaps; regulation is not a defence.
Assessment not reviewed after entering a new market or acquiring a business.ISO 37001 cl.4.5Review on change; the defence is judged on procedures at the time of the offence.
Due diligence depth uniform rather than calibrated to assessed risk.ISO 37001 cl.8.2Tier due diligence; uniform depth over-burdens low risk and under-examines high risk.
Fraud risk not assessed despite the September 2025 offence.ECCTAExtend the assessment to fraud committed for the organisation's benefit; it is a separate offence.
No top level commitment evidenced beyond a signed policy.Bribery Act guidance, principle 1Evidence engagement: resourcing decisions, escalations handled, communication from leadership.
Training generic rather than targeted at the assessed high-risk roles.ISO 37001 cl.7.3Target training at people performing the transactions the assessment identified.
Monitoring and review principle unaddressed.Bribery Act guidance, principle 6Define what is monitored, how often, and what happens when something is found.
Assessment undated or unowned.ISO 37001 cl.4.5Date, sign and own it; an undated assessment cannot evidence procedures at a point in time.

Case in point

Case in point: the third offence nobody assessed for

The UK now has three failure to prevent offences. Bribery came first under the Bribery Act 2010, with adequate procedures as the defence. Facilitation of tax evasion followed under the Criminal Finances Act 2017, with reasonable procedures. The failure to prevent fraud offence under ECCTA came into force on 1 September 2025, applying to large organisations across all sectors, carrying an unlimited fine, with reasonable procedures as the only defence.

The Home Office guidance published in November 2024 was described by practitioners as remarkably prescriptive relative to its predecessors, and it states plainly that a thorough risk assessment is the foundation and that the other five principles should be informed by its results. The Serious Fraud Office signalled its intention to pursue the offence from the outset.

Many organisations arrived at September 2025 with a bribery risk assessment reviewed reasonably recently and no assessment at all of where fraud might be committed for the organisation's benefit. Those are overlapping but distinct exposures, and only one of them had been mapped.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

45fields
6 sections
Reference
CMP-043
Archetype
Assessment
Record ID
ABR-2026-000
Scoring
Residual band
Direction
Low is good
Singleton
Yes
Basis
ISO 37001 cl.4.5
Links
Links Conflict of interest, Procurement
Tags
Ethics, Bribery
Sections
6
Fields
45
Follow up fields
3
Repeating sections
0
Links out
4
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

10 fields
Text

Assessment ID*

Generated on save

Auto sequence. Format ABR-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

Scope Assessed*

Users

Assessed By*

Single Choice

Third Party Advice Taken*

Scored
  • Yes3 pts
  • No1 pt
Info

Facilitation Payments Are Still Illegal At Home

A small payment to speed up an inspection or a permit is normal practice in some markets and a criminal offence in the jurisdiction your company reports into.

Exposure

6 fields
Single Choice

Procurement Decisions Exposed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Permit And Inspection Interactions Exposed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Customer Relationships Exposed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Agents Or Intermediaries Used*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

High Risk Jurisdictions Involved*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Charitable Or Political Donations Made*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Controls

6 fields
Single Choice

Policy In Place And Communicated*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Gifts And Hospitality Register Maintained*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Approval Thresholds Defined*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Third Party Due Diligence Performed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Contract Clauses Included*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Facilitation Payments Prohibited Explicitly*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Assurance

6 fields
Single Choice

Training Delivered To Exposed Roles*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Reporting Route Available*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Expenses Reviewed For Red Flags*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Audit Coverage Includes This*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Concerns Raised And Handled*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Senior Commitment Demonstrated*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Related records

1 field
Text

Modern Slavery Assessment ID

OptionalLinked

The related labour standards assessment.

Links to CMP-042 Assessment ID

Outcome

16 fields
Single Choice

Residual Band*

Scored
  • Low, 1 to 45 pts
  • Medium, 5 to 94 pts
  • High, 10 to 142 pts
  • Very high, 15 to 191 pt
  • Extreme, 20 to 250 pts
Numeric Answer

Gaps Identified*

Scored
Single Choice

Controls Proportionate*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Action Plan Created*

Scored
  • Yes3 pts
  • Not needed3 pts
  • No0 pts
Single Choice

Feeds Management Review*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Date & Time

Next Assessment Due*

Pick List

Risk Assessment

OptionalFrom FDN-012 Risk Title
Text

Risk ID

OptionalLinked

Format RSK-2026-00000.

Links to FDN-012 Risk ID

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Compliance Lead*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

CMP-043 · record IDs look like ABR-2026-000 · Links Conflict of interest, Procurement

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The assessment is the foundation of three defences. What fails is the transaction detail nobody mapped and the review that lapsed after an acquisition.

KnowComply

Holds the assessment against markets, transaction types and third parties, and triggers review on acquisitions, new markets and intermediary changes.

Ella
Ella

Maps existing controls against assessed risks and surfaces the gaps, rather than allowing existing compliance to be asserted as coverage.

KnowContractor

Extends assessment and due diligence to associated persons, including agents and intermediaries who are not suppliers in the usual sense.

KnowTrain

Targets training at the roles performing the transactions the assessment identified, rather than delivering the same module to everyone.

This template lives in KnowComplyaudit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply

Glossary

Anti-Bribery Risk Assessment definitions and key terms

Associated person
Anyone performing services for or on behalf of the organisation: employees, agents, subsidiaries, contractors and intermediaries.
Adequate procedures
The Bribery Act 2010 section 7 defence standard, judged against six principles and proportionate to risk.
Reasonable procedures
The defence standard under the tax evasion and fraud offences. The Home Office has indicated it is no more onerous than adequate.
Facilitation payment
A small payment to secure or expedite a routine government action. Illegal under the Bribery Act; a narrow FCPA exception exists.
Six principles
Top level commitment, risk assessment, proportionate risk-based procedures, due diligence, communication including training, and monitoring and review.
Failure to prevent offence
A corporate offence turning on an associated person's act, without requiring proof of management knowledge or intent.
Red flag
An indicator warranting enhanced scrutiny: unusual commission, request for payment to a third country, political connection, refusal of contract terms.
Books and records provisions
FCPA accounting requirements for accurate records and adequate internal accounting controls, enforced independently of bribery itself.

FAQ

Frequently asked questions about anti-bribery risk assessment

Why is the risk assessment the foundation of the defence?+

Because the defences require procedures that are adequate or reasonable, and both are judged as proportionate to the risk faced. Proportionality is unarguable without an assessment establishing what the risk was. Home Office guidance on the fraud offence states directly that a thorough risk assessment is the foundation and that the other principles should be informed by its results.

What changed on 1 September 2025?+

The failure to prevent fraud offence under the Economic Crime and Corporate Transparency Act 2023 came into force in England and Wales. It applies to large organisations across all sectors, makes them criminally liable where an associated person commits fraud intending to benefit the organisation, carries an unlimited fine, and provides reasonable fraud prevention procedures as the only defence. It requires no proof of management involvement.

Do our existing compliance procedures count?+

They are a starting point, not a defence. The guidance advises against duplicating existing work while making clear that existing regulatory compliance mechanisms do not automatically amount to reasonable procedures. The correct approach is to map what you have against the risks identified in this assessment and record where the gaps are.

Are small organisations affected?+

Directly, only where they meet the large organisation threshold. Indirectly, substantially: a smaller business may be an associated person of a large organisation and find fraud prevention requirements flowed down contractually. The practical effect is that the obligation propagates through supply chains well beyond the entities in scope.

How often should the assessment be reviewed?+

Annually as a minimum, and on any material change: entering a new market, acquiring a business, changing the intermediary model, or a significant change in the regulatory environment. The defence is judged on the procedures in place at the time of the offence, so an assessment describing a business you no longer are supports nothing.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.